# Geoip not reading dot expanded field (or any field, actually)

**URL:** https://discuss.elastic.co/t/geoip-not-reading-dot-expanded-field-or-any-field-actually/216929
**Category:** Elasticsearch
**Created:** [January 29, 2020, 12:12am UTC](https://discuss.elastic.co/t/geoip-not-reading-dot-expanded-field-or-any-field-actually/216929 "2020-01-29T00:12:07Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![AddChickpeas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/addchickpeas/32/44414_2.png) [@AddChickpeas](https://discuss.elastic.co/u/AddChickpeas)
#### Post date: [January 29, 2020, 12:12am UTC](https://discuss.elastic.co/t/geoip-not-reading-dot-expanded-field-or-any-field-actually/216929/1 "2020-01-29T00:12:07Z")

</div>

Hello,

I've been trying to get geoip working on field with dot notation without much luck.

**EDIT** : So this is happening even when not using nested fields. Same error either way. I'm using Fluentd so maybe the way it outputs the data is somehow not jiving with ES?

The field is coming in as "source.ip" as a single field. Since this won't work with the geoip processor, I reindexed a test index using dot expander so the source.ip field shows up like below in the \_doc:

```
 {
      "_index": "test.infr.event.network-paloalto-expand",     
      "_source": {
        "destination.port": "0",
        "source": {
          "ip": "11.111.111"
        },  
        "destination.ip": "111.11.111",
        "network.transport": "udp",
        "event.action": "allow",
        "@timestamp": "2020-01-28T23:43:29.000000000+00:00",
        "source.port": "53",
        "host.name": "hostname"
      },
      "fields": {
        "@timestamp": [
          "2020-01-28T23:43:29.000Z"
        ]
      },
      "sort": [
        1580255009000
      ]
    }

```

I then tried to run these dot expanded documents through a geoip processor to no luck. It's still giving me the `field [source] not present as part of path [source.ip]"` error.

```
Here is my processor: 
"sourcegeoip" : {
    "description" : "Add geoip info",
    "processors" : [
      {
        "geoip" : {
          "field" : "source.ip"
        }
      }
    ]
  }

```

And this is the reindex I ran:

```
POST _reindex
{
  "source": {
    "index": "test.infr.event.network-paloalto-expand"
  },
  "dest": {
    "index": "test.infr.event.network-paloalto-expand-geo",
    "pipeline" : "sourcegeoip"
  }
}

```

It is properly being recognized as an IP with this in the index template:

```
 "source": {
        "properties": {
          "address": {
            "type": "keyword",
            "ignore_above": 1024
          },
         ...
          },
          "ip": {
            "type": "ip"

```

I was under the impression that this would [work similar to nested conditionals](https://www.elastic.co/guide/en/elasticsearch/reference/current/ingest-conditional-nullcheck.html), but that doesn't seem to be the case.

Is what I am trying just not possible? In that case, is my only option to clone the field and create the geoip from there?

edit:

It works fine when I manually enter a document using

```
PUT test.infr.event.network-paloalto-expand/_doc/my_id?pipeline=sourcegeoip
{
  "source" : {
    "ip": "8.8.8.8"
    }
}
```

---

<div class="post-metadata">

### Author: ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)
#### Post date: [January 29, 2020, 3:09pm UTC](https://discuss.elastic.co/t/geoip-not-reading-dot-expanded-field-or-any-field-actually/216929/2 "2020-01-29T15:09:17Z")

</div>

can you provide a **minimal, but full** reproduction, including index creation, document creation, pipeline creation, reindex operation.

if someone tries to reproduce this, a lot of assumptions will be made, which means, trying to reproduce your problem ends up in different execution paths then yours, which will make it much harder to debug this issue.

Thanks!

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [February 26, 2020, 3:09pm UTC](https://discuss.elastic.co/t/geoip-not-reading-dot-expanded-field-or-any-field-actually/216929/3 "2020-02-26T15:09:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
